nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #251

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A…

The correct answer is C. Untrust (Any) to DMZ (10.1.1.1), web-browsing -Allow D. Untrust (Any) to DMZ (10.1.1.1), ssh -Allow. Explanation/Reference:

NAT and Security Policy

Question

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.) Which two security policy rules will accomplish this configuration? (Choose two.)

Exhibit

PSE-PLATFORM question #251 exhibit

Options

  • AUntrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
  • BUntrust (Any) to Untrust (10.1.1.1), ssh -Allow
  • CUntrust (Any) to DMZ (10.1.1.1), web-browsing -Allow
  • DUntrust (Any) to DMZ (10.1.1.1), ssh -Allow
  • EUntrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow

How the community answered

(69 responses)
  • A
    28% (19)
  • B
    6% (4)
  • C
    55% (38)
  • E
    12% (8)

Explanation

Explanation/Reference:

Topics

#DNAT#NAT policy#security policy zone matching#destination NAT

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice